CVE-2016-7477: Null Pointer Dereference
Published Feb 15, 2017
·Updated
The ffputpixels8xy2mmx function in rndtemplate.c in Libav 11.7 allows remote attackers to cause a denial of service (invalid memory access and crash) via a crafted mp3 file. NOTE: this issue was originally reported as involving a NULL pointer dereference.
Affected Software
1 affected component
Libav Libav=11.7
Event History
Feb 15, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7477?
CVE-2016-7477 has a severity level that allows remote attackers to cause a denial of service.
2
How do I fix CVE-2016-7477?
Fixing CVE-2016-7477 involves upgrading Libav to the latest version beyond 11.7.
3
What causes the denial of service in CVE-2016-7477?
The denial of service in CVE-2016-7477 is caused by an invalid memory access triggered by a crafted MP3 file.
4
Is CVE-2016-7477 specific to certain software versions?
Yes, CVE-2016-7477 specifically affects Libav version 11.7.
5
Can CVE-2016-7477 be exploited remotely?
Yes, CVE-2016-7477 can be exploited remotely by sending a specially crafted MP3 file.